CRISC Certified in Risk and Information Systems Control practice questions

251 free questions with answers and explanations.

Practice test
  1. 101.A financial services organization is considering a new product offering that involves complex algorithmic trading and introduces new data privacy challenges. The regulatory landscape for such products is rapidly evolving. To proactively manage compliance risks and ensure the product meets all current and future regulatory requirements, which approach should the organization adopt?Governance
  2. 102.A multinational corporation is expanding its operations into a new region with a highly diverse cultural landscape and varying legal interpretations of intellectual property (IP) rights. The corporate legal team has developed a global IP protection policy. However, local business units are finding it challenging to implement this policy effectively due to the local nuances. To address this, which of the following is the MOST important organizational structure or role to establish?Governance
  3. 103.A multinational corporation is expanding its operations into a new region with a highly diverse legal and regulatory landscape. The board of directors is concerned about ensuring compliance across all new jurisdictions while maintaining operational efficiency. Which of the following is the MOST effective approach to manage this challenge?Governance
  4. 104.An organization is developing a new mobile banking application. During the design phase, the security architect emphasizes the importance of ensuring that the application continues to function even if a single component fails. Which key principle of secure system design is the architect advocating?Information Technology and Security
  5. 105.A retail company is planning to launch a new e-commerce website. The project team is considering various security controls. They decide to implement a Web Application Firewall (WAF) to protect against common web-based attacks like SQL injection and cross-site scripting (XSS). This implementation is an example of which type of security control?Information Technology and Security
  6. 106.A financial services organization is implementing a new customer relationship management (CRM) system that will store highly sensitive client data. The project team is evaluating various security controls to protect this data. Which of the following would be considered a detective control?Information Technology and Security
  7. 107.A global manufacturing company is implementing an Industrial Control System (ICS) for its production lines. Due to the highly specialized nature of the equipment and the potential for significant physical damage from cyberattacks, the company decides to isolate the ICS network completely from the corporate IT network and the internet. Which security principle is being applied here?Information Technology and Security
  8. 108.An organization is deploying a new cloud-based application that processes sensitive customer data. The Chief Information Security Officer (CISO) is concerned about the potential for data breaches due to misconfigurations or vulnerabilities in the cloud environment. To address this, the CISO mandates a review process that ensures all cloud security configurations adhere to established benchmarks (e.g., CIS Benchmarks) and that infrastructure-as-code templates are scanned for security flaws before deployment. Which security concept is the CISO primarily emphasizing?Information Technology and Security
  9. 109.A global manufacturing company is expanding its operations into new markets. The company's risk management team is tasked with identifying potential risks associated with these new ventures, including geopolitical instability, new regulatory compliance requirements, and cultural differences affecting business practices. Which type of risk is the team primarily focusing on in this scenario?Information Technology and Security
  10. 110.A company is implementing a new cloud-based enterprise resource planning (ERP) system. The project team identifies that a critical integration with the legacy payroll system introduces a significant data privacy risk if not handled securely. To address this, they decide to use a secure API gateway, implement end-to-end encryption for data in transit, and conduct a privacy impact assessment (PIA). This scenario BEST illustrates which aspect of risk management?Information Technology and Security
  11. 111.A company is implementing a new enterprise resource planning (ERP) system. The project manager is tasked with ensuring that all necessary security requirements are identified and integrated throughout the project lifecycle. Which of the following project management concepts is MOST relevant to this task?Information Technology and Security
  12. 112.An organization is developing a new cloud-native application. To ensure security is integrated from the start, development teams are required to perform security testing at each stage of the development process. Which of the following security testing methods is BEST suited for identifying design flaws and vulnerabilities early in the SDLC, before coding is complete?Information Technology and Security
  13. 113.A company is implementing a new cloud platform and is concerned about vendor lock-in and the ability to easily migrate services between different cloud providers in the future. Which of the following architectural considerations would BEST address these concerns?Information Technology and Security
  14. 114.A healthcare organization is developing a new mobile application for patient data access. The project team is considering various security frameworks to guide their development process. They need a framework that provides detailed guidance on securing personal health information (PHI) and ensuring compliance with healthcare-specific regulations. Which of the following frameworks would be MOST appropriate for this context?Information Technology and Security
  15. 115.A financial institution is implementing a new customer relationship management (CRM) system. During the risk assessment, it is identified that a critical component of the system relies on a third-party vendor with a history of minor security incidents. The institution decides to implement additional internal monitoring and a more stringent service level agreement (SLA) with the vendor. Which of the following risk responses does this scenario primarily demonstrate?Information Technology and Security
  16. 116.A new project is being initiated to develop a mobile application for a healthcare provider. The project manager is conducting an initial risk assessment. Which of the following frameworks would be MOST appropriate for guiding the security and privacy considerations throughout the entire Systems Development Life Cycle (SDLC) for this project?Information Technology and Security
  17. 117.A software development team is adopting a 'shift left' security approach for a new application. During which phase of the Software Development Life Cycle (SDLC) would security architecture reviews and threat modeling MOST effectively be conducted to align with this approach?Information Technology and Security
  18. 118.A financial institution is evaluating its disaster recovery plan. During a recent test, it was discovered that the recovery time objective (RTO) for its core banking system was not met due to extensive data restoration procedures. Which of the following is the MOST appropriate immediate action for the institution to take?Information Technology and Security
  19. 119.A global manufacturing company is expanding its operations into new markets. The company's risk management team is tasked with identifying and assessing risks associated with this expansion, including geopolitical instability, regulatory compliance in new regions, and supply chain disruptions. Which type of risk is MOST prominently being addressed by the risk management team in this scenario?Information Technology and Security
  20. 120.An organization is conducting a business impact analysis (BIA) for its critical applications. One application, a customer relationship management (CRM) system, is identified as having a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 1 hour. What does the RPO of 1 hour specifically indicate for this CRM system?Information Technology and Security
  21. 121.A data center experiences a complete power outage due to a regional grid failure. The incident response team successfully switches to backup power, but several non-critical systems are offline for 12 hours. The Business Continuity Plan (BCP) specifies that critical systems must be restored within 4 hours, and non-critical systems within 24 hours. Which of the following metrics was successfully met in this scenario?Information Technology and Security
  22. 122.A manufacturing company is implementing a new Industrial Control System (ICS) to automate its production line. The ICS will be connected to the corporate network for monitoring and reporting. To protect the operational technology (OT) environment from threats originating from the IT network, which security control is MOST critical to implement?Information Technology and Security
  23. 123.A multinational corporation is considering migrating its critical enterprise resource planning (ERP) system to a public cloud provider. The Chief Information Security Officer (CISO) is concerned about the shared responsibility model. Which of the following responsibilities typically remains with the customer in an Infrastructure as a Service (IaaS) model?Information Technology and Security
  24. 124.A Chief Information Officer (CIO) is evaluating the organization's information security program and wants to ensure it is aligned with industry best practices and regulatory requirements. The CIO is particularly interested in a security framework that provides a comprehensive, risk-based approach to managing information security. Which framework would be MOST suitable for this purpose?Information Technology and Security
  25. 125.A critical infrastructure organization is implementing a new industrial control system (ICS). Due to the potential for severe physical and environmental damage from a cyberattack, the organization is prioritizing controls to prevent unauthorized access and modification to the ICS. Which of the following security principles is MOST critical to uphold in this context?Information Technology and Security
  26. 126.A project manager is overseeing the implementation of a new enterprise resource planning (ERP) system. During the planning phase, a key stakeholder expresses concern that the project might not deliver the expected business benefits due to insufficient user adoption. Which of the following risk categories does this concern PRIMARILY fall under?Information Technology and Security
  27. 127.An organization is conducting a post-incident review after a significant data breach. The review team identifies that while technical controls (firewalls, IDS) were in place, human error (a click on a phishing link) was the root cause, and the security awareness training program was outdated and ineffective. Based on this finding, the organization should prioritize updating and enhancing its security awareness training program. This action represents an improvement in which type of control?Information Technology and Security
  28. 128.A software development company is adopting a DevSecOps approach. As part of this, they are integrating security tools and practices throughout the entire software development lifecycle (SDLC), from design to deployment. A key practice being implemented is automated security testing within the continuous integration/continuous delivery (CI/CD) pipeline, ensuring that code is scanned for vulnerabilities with every commit. This practice directly supports which core principle of DevSecOps?Information Technology and Security
  29. 129.An organization is preparing for an external audit of its information security management system (ISMS). The audit will assess compliance with ISO/IEC 27001. Which of the following activities is MOST crucial for the organization to complete BEFORE the audit to demonstrate adherence to the standard?Information Technology and Security
  30. 130.A financial institution is implementing a new online banking platform. During the project's risk assessment, it's identified that a potential denial-of-service (DoS) attack could disrupt services, leading to significant financial losses and reputational damage. The institution decides to purchase cyber insurance that specifically covers losses incurred from such attacks. Which risk response strategy is being employed?Information Technology and Security
  31. 131.A software development team is adopting a DevSecOps approach. To ensure security is integrated from the earliest stages of the development lifecycle, which of the following practices should be implemented FIRST?Information Technology and Security
  32. 132.A security incident response team discovers that an unauthorized third party has gained access to a critical server hosting customer data. The immediate priority is to prevent further compromise and data exfiltration. Which of the following incident response phases should the team primarily focus on at this stage?Information Technology and Security
  33. 133.A software development company is adopting a DevSecOps approach. As part of this, they are focusing on integrating security activities earlier in the Software Development Life Cycle (SDLC). Which of the following practices BEST represents this 'shift left' security principle?Information Technology and Security
  34. 134.A financial services firm is updating its incident response plan. The firm has identified that phishing attacks are the most common initial vector for security breaches. To improve their response capability, they decide to implement an automated email analysis tool that quarantines suspicious emails and provides immediate alerts to the security operations center (SOC). This action primarily aims to improve which phase of the incident response lifecycle?Information Technology and Security
  35. 135.A manufacturing company relies heavily on an industrial control system (ICS) for its production line. A recent vulnerability scan identified several unpatched systems and weak authentication mechanisms within the ICS network. The risk manager calculates the potential annual loss expectancy (ALE) from a successful cyberattack on the ICS. Given an Asset Value (AV) of $5,000,000, an Exposure Factor (EF) of 0.40, and an Annualized Rate of Occurrence (ARO) of 0.25, what is the ALE?Information Technology and Security
  36. 136.A risk manager is conducting a qualitative risk assessment for a new product launch. The team identifies a risk event: 'Failure of a key third-party API leading to service disruption.' They assess the likelihood as 'Medium' and the impact as 'High'. Based on this, what is the MOST appropriate initial risk rating?Information Technology and Security
  37. 137.A multinational corporation is undergoing a major digital transformation, migrating critical business applications and data to a public cloud environment. The Chief Risk Officer (CRO) is concerned about the inherent risks associated with cloud adoption, particularly vendor lock-in, data residency, and compliance with various international regulations. Which of the following frameworks would provide the MOST comprehensive guidance for managing these specific cloud-related risks?Information Technology and Security
  38. 138.A company is conducting a business impact analysis (BIA) to prioritize its critical business functions and supporting IT systems. The BIA team has identified that the maximum tolerable period for an outage of its online sales platform is 4 hours. What does this 4-hour period represent?Information Technology and Security
  39. 139.A risk manager is evaluating the effectiveness of security controls for a critical asset. The current controls reduce the likelihood of a successful attack from 80% to 10% and the impact from $1,000,000 to $50,000. What is the residual risk after implementing these controls?Information Technology and Security
  40. 140.A company is evaluating its current information security posture. The CISO receives a report detailing that the organization has a low maturity level in its vulnerability management program, with many identified vulnerabilities remaining unpatched for extended periods. This indicates a weakness in which of the following core information security concepts?Information Technology and Security
  41. 141.A company is integrating a third-party cloud service for its customer data. The service provider's standard contract includes a clause stating that the provider is not liable for data breaches resulting from misconfigurations by the customer. Which of the following risk management principles is BEST addressed by clearly understanding this clause?Information Technology and Security
  42. 142.A large e-commerce company is experiencing a significant increase in distributed denial-of-service (DDoS) attacks targeting its online storefront during peak sales periods. The security team has implemented advanced DDoS protection services and traffic filtering rules. However, the attacks are still causing occasional service disruptions. What is the MOST likely next step the risk manager should recommend to address the remaining risk?Information Technology and Security
  43. 143.An organization is conducting a security audit of its cloud infrastructure. The auditor discovers that several critical virtual machines (VMs) are running with default administrative credentials and unpatched operating systems. Which of the following risk management strategies is MOST appropriate to address these findings immediately?Information Technology and Security
  44. 144.A healthcare provider is developing a new electronic health record (EHR) system. The project manager is conducting a risk assessment and identifies a high probability of data breaches due to vulnerabilities in the system's authentication module. The team proposes implementing multi-factor authentication (MFA) and conducting regular penetration tests. This approach aligns with which of the following risk management principles?Information Technology and Security
  45. 145.A security auditor is reviewing an organization's incident response plan. The auditor notes that while the plan includes detailed steps for containment and eradication, it lacks clear guidelines for post-incident activities aimed at preventing recurrence. Which phase of the incident response lifecycle is inadequately addressed?Information Technology and Security
  46. 146.A company is considering whether to invest in a new security solution that costs $50,000 annually. The solution is expected to reduce the Annual Loss Expectancy (ALE) from $150,000 to $70,000. What is the return on investment (ROI) for this security solution in the first year?Information Technology and Security
  47. 147.A cloud service provider (CSP) is offering an Infrastructure as a Service (IaaS) solution. A customer is concerned about the security responsibilities for the operating system and applications running on the provisioned virtual machines. According to the shared responsibility model, who is primarily responsible for securing these components?Information Technology and Security
  48. 148.A security operations center (SOC) manager is reviewing their organization's risk register. They notice that many identified risks lack clear descriptions of the existing controls in place to mitigate them, or the residual risk level post-control implementation. This omission makes it difficult to prioritize remediation efforts and understand the organization's true risk posture. Which essential element of a comprehensive risk register is MOST overlooked in this situation?IT Risk Assessment
  49. 149.A software development company is migrating its code repositories to a new platform. The risk team is using a qualitative risk analysis approach to assess potential impacts. They are categorizing risks based on a matrix that considers likelihood and impact. Which of the following factors is MOST critical to ensure the consistency and objectivity of the qualitative risk ratings across different assessors?IT Risk Assessment
  50. 150.A healthcare organization is conducting an IT risk assessment for its new patient portal. During the risk identification phase, the team uses a systematic approach to uncover potential threats and vulnerabilities. Which of the following techniques is BEST suited for identifying both known and unknown risks by breaking down the system into its components and analyzing potential failure points?IT Risk Assessment